Independent information resource Product security · EU CRA
Engineering / 07

Secure development as an implementation practice

A practical workflow linking product risk, architecture, components, verification and maintenance.

IN BRIEF

A secure development lifecycle is a useful implementation framework. The CRA requires risk assessment to inform decisions throughout planning, design, development, production, delivery and maintenance; it does not prescribe this page’s exact workflow.

Engineer examining a circuit board beside industrial hardware and technical drawings
PRODUCT ENGINEERING / ILLUSTRATIVE IMAGE
01 / 03

Frame the system

Define product functions, trust boundaries, dependencies and foreseeable use. Record assumptions and security risks before choosing controls.

  • Product and component inventory
  • Threat and risk assumptions
  • Security requirements tied to design decisions
02 / 03

Build and verify

Review architectures and components, configure secure defaults, test relevant security properties and track findings to remediation. Keep traceable evidence for product versions.

03 / 03

Maintain in use

Plan security updates, support communications, vulnerability intake and post-release review. Feed newly discovered issues back into the risk assessment.

REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.